Privacy Policy
Effective Date: June 30, 2026
This Privacy Policy explains how ML Digital LLC, doing business as Movement Lab Digital (“Movement Lab Digital,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you visit movementlabdigital.com, communicate with us, book a call, subscribe to communications, purchase or receive services from us, or otherwise interact with us.
This Privacy Policy should be read together with our Terms and Conditions, Cookie Policy, and any applicable proposal, order form, client agreement, statement of work, Business Associate Agreement (“BAA”), or other written agreement between you and us.
Our website and services are intended for business users and are not intended for children or individuals under 18 years of age.
IMPORTANT HEALTHCARE AND HIPAA NOTICE
Movement Lab Digital provides digital marketing and related business services to physical therapy practices and other business clients. This Privacy Policy is not a HIPAA Notice of Privacy Practices for any healthcare provider.
Our agency website is not intended to collect medical, health, insurance, injury, pain, diagnosis, treatment, or other patient health information. Do not submit such information through our general website forms, booking forms, email inboxes, or other unapproved channels.
When we process patient or prospective-patient information on behalf of a healthcare client, we do so only as permitted by the applicable client agreement, BAA, and applicable law.
WHO WE ARE
ML Digital LLC is a Wyoming limited liability company operating under the brand Movement Lab Digital.
For personal information collected through our own website, sales process, forms, communications, and business operations, ML Digital LLC is generally the business, controller, or similar responsible entity, depending on the law that applies.
For certain client-service activities, including advertising, landing pages, appointment workflows, CRM support, reporting, and marketing operations, we may process personal information on behalf of a client. In those circumstances, the client may be the controller, business, covered entity, or other primary decision-maker, while we may act as a processor, service provider, contractor, business associate, or similar role under applicable law and the written agreement.
Contact Information
Legal Entity: ML Digital LLC
Brand Name: Movement Lab Digital
Mailing Address:
ML Digital LLC
30 N Gould St Ste R
Sheridan, Wyoming 82801
United States
Email: support@movementlabdigital.com
Website: movementlabdigital.com
PERSONAL INFORMATION WE COLLECT
Depending on how you interact with us, we may collect the following categories of personal information.
Identity Data may include your name, business role, job title, company or clinic name, and other information you provide to identify yourself.
Contact Data may include your business email address, phone number, mailing address, billing address, and other contact details.
Business and Client Data may include clinic name, website URL, business location, monthly revenue range, advertising budget, business goals, service interests, lead-generation goals, appointment-booking goals, and information provided during sales, onboarding, strategy, support, or client communications.
Financial and Payment Data may include billing details, invoice information, payment status, transaction records, fees, charges, and related accounting records. We do not intentionally store complete payment-card details ourselves. Card payments are processed by third-party payment processors, such as Stripe.
Transaction Data may include details about purchases, service packages, setup fees, appointment-based fees, invoices, receipts, payments, refunds, and other records of transactions with us.
Technical Data may include internet protocol address, browser type and version, device type, operating system, time zone, approximate location, device identifiers, pages viewed, referring URLs, session information, and other technical information related to use of our website.
Usage Data may include information about how you interact with our website, forms, booking pages, emails, advertisements, and other online services.
Marketing and Communications Data may include communication preferences, opt-in and opt-out records, email or SMS responses, survey responses, feedback, and records of communications with us.
Call, Meeting, and Sales Data may include information provided when booking or attending a call, meeting notes, recordings where legally permitted, transcripts where used, and follow-up tasks or summaries.
Client Access and Platform Data may include account permissions, access credentials, account IDs, advertising-account information, CRM access, website CMS access, calendar access, analytics access, Google Ads access, Meta Business Manager access, Google Business Profile access, Google Search Console access, and similar information that a client authorizes us to access for the purpose of providing services.
Healthcare Client Data may include patient or prospective-patient information that we process on behalf of a healthcare client under an approved workflow. For ordinary appointment attribution and reporting, this information is generally limited to:
-
Name
-
Email address
-
Phone number
-
Appointment date and time
-
Appointment status
-
Agreed lead-source and attribution data
We do not ordinarily request or require diagnosis details, injury information, treatment history, insurance information, clinical notes, or other clinical details. Any request for expanded PHI requires separate written approval, a valid BAA, and an approved HIPAA-appropriate workflow.
HOW WE COLLECT PERSONAL INFORMATION
We may collect personal information directly from you when you:
-
Submit a contact form or book a call
-
Subscribe to communications
-
Request information, a proposal, or marketing materials
-
Complete client onboarding materials
-
Sign an agreement or make a payment
-
Communicate with us by email, phone, SMS, video conference, social media, or another communication channel
-
Provide feedback, testimonials, or survey responses
We may automatically collect certain Technical Data and Usage Data through cookies, server logs, analytics tools, and similar technologies used on our own agency website. For more information, please see our Cookie Policy.
We may receive personal information from third parties and publicly available sources, including referral partners, business directories, search engines, public business registries, publicly available websites, advertising networks, payment processors, scheduling providers, CRM providers, clients, and client-authorized platforms.
We may also collect business contact information from publicly available sources or legitimate third-party databases for business-to-business outreach where permitted by applicable law.
HOW WE USE PERSONAL INFORMATION
We may use personal information to:
-
Respond to inquiries and communicate with prospects, clients, and website visitors
-
Schedule calls, demonstrations, meetings, and consultations
-
Evaluate whether a prospect or business is a suitable fit for our services
-
Prepare proposals, agreements, invoices, payment links, and onboarding materials
-
Provide digital marketing, advertising, local SEO, landing page, CRM, appointment-booking, reporting, and related services
-
Manage payments, billing, accounting, disputes, and collections
-
Maintain and protect our website, systems, accounts, and business operations
-
Improve our website, services, sales process, content, advertising, and communications
-
Send newsletters, offers, educational content, updates, and other marketing communications, subject to applicable consent and opt-out requirements
-
Conduct lawful business-to-business outreach
-
Comply with legal obligations, enforce agreements, protect our rights, prevent fraud, and resolve disputes
-
Process healthcare-client data only as necessary to provide approved services and only as permitted by the applicable client agreement, BAA, and law
LEGAL BASES FOR PROCESSING
Where GDPR, UK GDPR, or similar laws apply, we may rely on one or more of the following legal bases:
Performance of a Contract. Processing may be necessary to enter into or perform a contract with you or your business.
Legitimate Interests. Processing may be necessary for our legitimate business interests, including operating and improving our business, providing services, communicating with business prospects and clients, conducting lawful B2B marketing, securing systems, preventing fraud, and enforcing agreements.
Consent. We may rely on consent where required, including for certain marketing communications, non-essential cookies, tracking technologies, or call recording.
Legal Obligation. Processing may be necessary to comply with legal, tax, accounting, regulatory, security, or legal-process obligations.
MARKETING COMMUNICATIONS
We may send marketing communications if you request information, submit a form, book a call, purchase services, subscribe to communications, interact with our content, or if we obtain your business contact information from lawful sources and you have not opted out.
You may unsubscribe from marketing emails by using the unsubscribe link in the email or by contacting support@movementlabdigital.com.
If you receive marketing SMS messages from us, you may opt out by following the instructions in the message, such as replying STOP where available, or by contacting us.
Even if you opt out of marketing communications, we may continue to send service-related, transactional, billing, security, legal, or administrative communications.
We do not sell personal information to third parties for money. We do not share personal information with third parties so they can independently market unrelated products or services to you without your consent.
COOKIES, TRACKING TECHNOLOGIES, AND ONLINE ADVERTISING
We may use cookies and similar technologies on our own agency website. These may include strictly necessary cookies, analytics cookies, advertising cookies, conversion-tracking technologies, and similar tools.
Depending on what is actually installed and enabled on our agency website, these tools may include Wix tools, Google Analytics, Google Tag Manager, Google Ads conversion tracking, Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, Hotjar, or similar technologies.
Where required by law, we will request consent before placing non-essential cookies or similar technologies on your device. You may be able to manage non-essential cookie preferences through our cookie banner, browser settings, or other available preference tools.
Some advertising, analytics, retargeting, or similar activities may be considered targeted advertising, sharing, or cross-context behavioral advertising under certain privacy laws. Where applicable, you may have the right to opt out of those activities.
IMPORTANT HEALTHCARE TRACKING RESTRICTIONS
The tracking technologies described above apply only to Movement Lab Digital’s own agency website and non-PHI business activities, where actually used.
We do not knowingly use Meta Pixel, Google Analytics, remarketing pixels, enhanced conversions, offline conversion uploads, Customer Match, or similar tracking or advertising-audience tools in healthcare-client workflows involving PHI or patient-related health information.
We do not knowingly upload, disclose, or use patient data, PHI, or health-related data in Meta, Google, or other advertising-audience tools.
HOW WE DISCLOSE PERSONAL INFORMATION
We may disclose personal information to service providers and other recipients as necessary for the purposes described in this Privacy Policy, including:
-
Website hosting, website-building, and platform providers
-
Email, productivity, and cloud-storage providers
-
Scheduling, video-conferencing, and booking providers
-
CRM, marketing automation, and customer-support providers
-
Payment, invoicing, accounting, and banking providers
-
Advertising, analytics, tag-management, and conversion-tracking providers
-
Project-management, documentation, and operational providers
-
Lawyers, accountants, insurers, auditors, consultants, and other professional advisors
-
Clients and client-authorized platforms where necessary to provide requested services
-
Government authorities, regulators, courts, law enforcement, or other parties where required by law or legal process
-
Buyers, investors, lenders, successors, or advisors in connection with a merger, acquisition, financing, sale of assets, restructuring, or similar business transaction
Examples of providers we may use for ordinary non-PHI business activities include Wix, Google Workspace, Google Calendar, Wix Bookings, Stripe, Wise, Mercury, QuickBooks, GoHighLevel, Zoom, Google Meet, and other similar providers.
A provider’s inclusion in this Privacy Policy does not mean that it is approved to receive or process PHI.
HEALTHCARE CLIENT DATA, PHI, AND HIPAA-APPROPRIATE SYSTEMS
For physical therapy clinics and other healthcare clients, we use only approved HIPAA-appropriate third-party systems for workflows in which we create, receive, maintain, transmit, store, or process PHI.
For a PHI-related workflow, our policy is to use only systems that have been approved for that workflow, are appropriately configured, have the required safeguards in place, and are covered by a BAA or other required contractual protections where applicable.
Not every third-party platform used in our business is approved or permitted for PHI. A platform may be used for ordinary non-PHI business, advertising, administrative, or operational purposes without being approved for PHI.
Before we create, receive, maintain, or transmit PHI on behalf of a healthcare client, the parties must execute an applicable BAA and establish an approved HIPAA-appropriate workflow.
If a BAA conflicts with this Privacy Policy, the Terms and Conditions, or another client agreement regarding PHI, the BAA controls.
We do not use patient data, PHI, or identifiable healthcare-lead data for our own independent marketing purposes.
We do not knowingly permit contractors, media buyers, virtual assistants, developers, or other third parties to access PHI unless the client has approved that access in writing and all required privacy, security, and BAA arrangements are in place.
We limit access to PHI to Lazar Kostic unless the client gives prior written approval for additional access and we confirm that the additional access is permitted under the applicable BAA and applicable law.
Healthcare clients remain responsible for their own privacy notices, patient consents, HIPAA obligations, professional obligations, advertising claims, forms, tracking technologies, patient communications, CRM practices, and other legal or operational requirements that apply to them.
SECURITY
We use reasonable administrative, technical, and organizational measures designed to protect personal information from accidental loss, unauthorized access, misuse, disclosure, alteration, or destruction.
Our safeguards may include access controls, limited-access practices, password protection, multi-factor authentication where available, vendor controls, confidentiality obligations, and other reasonable security measures.
No method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security.
If we discover a suspected security incident or unauthorized use or disclosure involving PHI, we will notify the applicable healthcare client within five business days after discovery, subject to the applicable BAA and applicable law.
DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business records, manage client relationships, comply with legal, accounting, tax, reporting, and security obligations, resolve disputes, collect fees, enforce agreements, and protect our rights.
Retention periods may depend on the nature and sensitivity of the information, the purposes for which it was collected, whether we have an ongoing relationship with you, legal or contractual requirements, tax and accounting obligations, potential disputes, and whether the information can be aggregated, de-identified, or anonymized.
Where we process personal information on behalf of a client, retention may be governed by the applicable client agreement, BAA, client instructions, and applicable law.
Upon termination of applicable healthcare services, we will return or securely delete PHI within thirty days where feasible, subject to legal retention obligations, technical limitations, vendor limitations, and the applicable BAA.
We may retain aggregated, de-identified, or anonymized information that no longer identifies an individual for analytics, reporting, benchmarking, service improvement, and business purposes.
INTERNATIONAL TRANSFERS
ML Digital LLC is organized in Wyoming, United States. Our agency may be operated from Serbia, and we may use service providers located in the United States, Serbia, Europe, or other countries.
Your personal information may be transferred to, stored in, or processed in countries that may have privacy laws different from those in your country of residence.
Where GDPR, UK GDPR, or similar laws apply, we take steps designed to protect personal information in accordance with applicable law, which may include data-processing agreements, standard contractual clauses, adequacy mechanisms, or other lawful transfer safeguards where required.
YOUR PRIVACY RIGHTS
Depending on where you live and applicable law, you may have the right to request:
-
Access to your personal information
-
Correction of inaccurate personal information
-
Deletion of personal information
-
Restriction of processing
-
Objection to certain processing
-
Portability of personal information
-
Withdrawal of consent
-
Information about certain disclosures or uses of personal information
-
Opt-out of marketing communications
-
Opt-out of targeted advertising, sharing, or cross-context behavioral advertising where applicable
These rights are not absolute. We may need to retain certain information for legal, contractual, tax, accounting, security, dispute-resolution, fraud-prevention, or legitimate business purposes.
To submit a privacy request, contact support@movementlabdigital.com. We may need to verify your identity before responding.
If you are an authorized agent making a request on behalf of another person, we may require proof of authorization and identity verification.
For patient or prospective-patient data we process on behalf of a healthcare client, privacy requests should generally be directed to the applicable healthcare provider or client. We will assist the client as required by the applicable BAA, client agreement, and law.
U.S. STATE PRIVACY RIGHTS
Certain U.S. state privacy laws may provide residents with additional rights, including rights to know, access, correct, delete, obtain a copy of, or opt out of certain processing of personal information.
We do not sell personal information for money.
Where applicable, you may opt out of targeted advertising, sharing, or cross-context behavioral advertising by using available cookie preference tools, browser settings, Global Privacy Control where supported, or by contacting support@movementlabdigital.com.
We do not knowingly sell or share the personal information of individuals under 18 years of age.
GDPR, UK GDPR, AND INTERNATIONAL PRIVACY RIGHTS
If GDPR, UK GDPR, or similar laws apply to you, you may have rights to access, correct, erase, restrict, or object to processing of your personal data, request portability, and withdraw consent where processing is based on consent.
You may also have the right to lodge a complaint with the applicable data protection authority.
CHILDREN’S PRIVACY
Our website and services are intended for business users and are not directed to individuals under 18 years of age.
We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact support@movementlabdigital.com, and we will take appropriate steps to delete the information where required by law.
TESTIMONIALS, CASE STUDIES, AND MEDIA
We may publish client testimonials, client names, logos, screenshots, campaign results, case studies, photos, videos, or other media only with the client’s prior written approval.
If a client provides patient testimonials, photos, videos, reviews, health-related stories, or similar patient-related content, the client is responsible for obtaining all required patient consents, authorizations, and permissions before providing the material to us.
We will not publicly disclose patient information.
THIRD-PARTY LINKS
Our website, emails, landing pages, or content may include links to third-party websites, plug-ins, applications, or services.
We do not control third-party websites or services and are not responsible for their privacy practices, security, availability, performance, or terms. Your use of third-party services is subject to the third party’s own policies and terms.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. When we make changes, we will update the Effective Date above.
If changes are material, we may provide additional notice where required by law.
No update to this Privacy Policy modifies an executed client agreement or BAA. Any amendment to an executed client agreement or BAA must be made according to its own terms.
CONTACT US
If you have questions about this Privacy Policy, our privacy practices, or your privacy rights, contact us at:
Movement Lab Digital / ML Digital LLC
Mailing Address:
30 N Gould St Ste R
Sheridan, Wyoming 82801
United States
Email: support@movementlabdigital.com
Website: movementlabdigital.com